Car Hacking

El Gran Saiyaman deteniendo un Chevrolet Corvette

I’ve spent the last few days non-stop around the house giving talks and lectures on Connected Car Risks. Although the term ‘connected car’ is pretty clear, let me explain it just in case one of my 6 followers (yes, one has unfollowed me 🙁 ) doesn’t know what it means: we’re talking about today’s cars and the ones coming in the future, connected to the outside world via the Internet or via street beacons that inform them of real-time traffic or weather conditions, roadworks or accidents, and help them make decisions once these cars become autonomous.

Talking about self-driving cars might seem like talking about a distant future, but that’s simply because we’re in Spain and the legislation here doesn’t allow it. In other countries, autonomous cars are already driving around in testing phase with a safety driver who only takes control in emergency situations.

As we’ve already said, these cars will be connected to what are known as smart-cities, where there are tons of connected elements and artificial intelligence processes capable of making decisions such as changing traffic light states based on traffic flow or rerouting buses from underused lines to others during peak moments, like right after a concert or a football match. All very modern and smart, with no need for some person to make the decision and press buttons.

Let’s get back to talking about cars. Or not, let’s talk about networks and connections. Or all of it together. The point is that these cars will receive information from the outside to, for example, decide the best route to get you home from work. With this information, they’ll set up their GPS to drive you through the least congested streets. But, what would happen if someone could alter this information or simply trick your GPS? Well, that’s basically what I’ve been talking about these days at various conferences. Sounds like science fiction to you? Well, check out the videos we recorded a few weeks ago straight from the presentation at RootedCON Valencia:

https://www.slideshare.net/mobile/rootedcon/carlos-sahuquillo-car-hacking-de-angelina-jolie-a-charlize-theron-rootedvlc2018

What is RootedCON?

RootedCON is a Security and Hacking conference held every year in two Spanish cities, Madrid and Valencia. It’s one of the leading conferences where vulnerabilities and papers that haven’t been disclosed before are presented, meaning the latest developments and discoveries get unveiled there… sort of like Paris Fashion Week… but for hackers.

This year, a colleague from GMV (Igor Robles) and I submitted a paper on Car Hacking without much hope that it would get accepted… but it did. You can’t show up at RootedCON with some generic presentation about where the bad guys are going to come from and what we should watch out for; you have to bring something tangible that people can actually verify empirically. So we gave a heads up a few days before the event and recommended that attendees not bring their own cars and instead use Valencia’s efficient public transport network:

The talk went so well and turned out to be so much fun that we’ve since been invited to several events dealing with connected cars, asking us to repeat more or less the same idea from Rooted but without getting into so many technical details (at Rooted, Igor tore apart a CANBUS frame and started explaining what each bit of information meant… at that event, people expected exactly that, but at these more institutional events, if I go into that level of detail people might walk out halfway through the talk and never invite us back). You should’ve seen the audience’s face when we showed how you could capture the events that travel through the car’s network when the steering wheel turns for park-assist (that automatic parking feature everyone’s obsessed with… I don’t quite get why, honestly — if you’ve got 12 cameras and sensors and the parked objects aren’t moving, parking a car in a spot isn’t exactly rocket science). The thing is, once you capture and clean up this information, it’s possible to inject it into the car at any moment, even when it’s not parking… can you imagine sending a steering wheel turn command to a car while it’s cruising at 120 km/h on a highway? Well, that’s not science fiction either — I recommend downloading the RootedCON presentation again to see for yourself.

By the way, off the back of RootedCON I was also interviewed on ‘Tecnología y Sentido Común’, the radio show for professionals in project management, service management, risk management, process management and IT Governance, hosted by the great Javier Peris. If you want to listen to the interview, it’s available from minute 48:00 onward, though I’d recommend listening to the whole podcast since it’s well worth it: Interview on the Tecnología y Sentido Común radio show

Other events and shindigs

I’m publishing this post from Málaga, where I’m attending the S-Moving Smart, Autonomous and Unmanned Vehicles Forum to take part in a panel discussion on Cybersecurity in connected cars. If you’re around Málaga and reading this in time, you’re welcome to join the Cybersecurity panel with this code:

On top of that, next week I’ll be in León at ENISE, the Cybersecurity Congress organized every year by the National Cybersecurity Institute, also to talk about the latest vulnerabilities discovered in connected cars and how the industry can tackle this whole bunch of technological challenges it’s about to face starting right now.

The best part of all this is that the new generations, who are the ones who’ll actually have to deal with this problem, are really interested in hearing this talk about connected car risks. So on November 6th I’ve been invited to speak about it at a network attacks event being held at the Polytechnic University of Valencia. Sorry I can’t share more details, but it’s a student-only event, so it’s not open to the general public.

And what do you all think about all this? It kind of feels like we’re much safer with a 15-year-old car that isn’t connected to anything and whose fanciest feature was a radio-CD player, right? Or are you the type who trusts technology, assuming someone must’ve already thought of all this by the time you buy a new car? Leave me your comments on the post, please — it really helps me know your opinion so I can keep tweaking the focus of these talks 🙂

Carlos Sahuquillo

Carlos Sahuquillo

'Haga lo que haga en la vida, siempre compito' - Jacques Villeneuve Reserva una sesión →

Sigue leyendo

Entradas relacionadas

Ver todo el blog
19 julio, 2018 · Automóvil y vehículos conectados

Webinar and podcast over Car Hacking

Idioma:CastellanoEnglish I’ve spent the last few days non-stop around the house giving talks and lectures on Connected Car Risks. Although the term…

Leer
29 mayo, 2018 · Automóvil y vehículos conectados

Forensic analysis of connected cars

Idioma:CastellanoEnglish I’ve spent the last few days non-stop around the house giving talks and lectures on Connected Car Risks. Although the term…

Leer
23 marzo, 2018 · Automóvil y vehículos conectados

First hit by an autonomous car

Idioma:CastellanoEnglish I’ve spent the last few days non-stop around the house giving talks and lectures on Connected Car Risks. Although the term…

Leer
Conversación

2 comentarios

Deja un comentario

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *

Este sitio usa Akismet para reducir el spam. Aprende cómo se procesan los datos de tus comentarios.